Junglewise Threat Intelligence

CVE-2026-27251: Adobe Experience Manager stored XSS in form fields

CVE-2026-27251 · Severity: medium · CVSS 5.4 · Published 2026-03-11

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a content management and digital asset platform widely used by enterprises to manage web content and customer experiences, is vulnerable to stored cross-site scripting (XSS). An attacker with low-level access could inject malicious scripts into form fields that execute when other users view the affected page, potentially allowing account takeover, credential theft, or unauthorized actions performed on behalf of legitimate users.

Technical details

The vulnerability is a stored XSS flaw in form field handling affecting Experience Manager versions 6.5.23 and earlier. The root cause is insufficient input validation and output encoding in vulnerable form components. An authenticated attacker with low privileges can inject malicious JavaScript that persists in the application database and executes in the browsers of any user who accesses the compromised page, without requiring additional user interaction. The attacker gains the ability to perform actions as the victim or steal sensitive information. No patch status is currently available from the advisory text.

Affected products

  • Adobe Experience Manager 6.5.23 and earlier

Timeline

  • 2026-03-11: disclosed

References